Take your IAM global

Fully isolate identity profile data with InCountry’s Sovereign Identity
identity-stack-image

Secure digital twins fully isolate identity profiles within a country

  • Avoid regulatory barriers and cost of cross-border data transfers
  • Simpler and more efficient than federating multiple orgs
  • Available globally beyond your identity vendor’s regions
  • Works with both Customer and Workforce identity
A new model for customer data protection

A new model for customer data protection

  • Store all PII, PHI, and PFI in its country of origin to avoid cross-border regulatory burden
  • Store cloaked profiles in your global Customer Identity and Access Management system (CIAM)
  • Customer services and sales teams in each country or regulatory area can access uncloaked data

InCountry’s comprehensive solution for IAM and CIAM data residency

Digital Twins
Digital Twins

Profile data is securely managed and isolated within a country.

Dialogs
Dialogs

Cloaks and uncloaks identity fields in registration, login, profile, and other forms.

Authorization
Authorization

Cloaks and uncloaks claims in JWT authorization tokens.

MFA
MFA

Multi-factor authorization via email and SMS with cloaked emails and phone numbers.

APIs
APIs

Requires no code changes with SCIM 2.0 and vendor API cloaking and uncloaking of fields.

Admin
Admin

Fully integrated so only admins within a country can see uncloaked data and manage users and groups.

 Comprihensive Solutions
Fully compatible with existing identity APIs

Fully compatible with existing identity APIs

  • SCIM 2.0 support
  • Vendor API support including Okta Workforce, Okta Auth0, WSO2 Asgardeo, and Strivacity.
  • JWT tokens are augmented with local claims
  • Access to individual records and fields continues to be controlled by the Identity Access Management system and source application’s policies
  • Seamlessly cloak and uncloak JWT claims for MCP and A2A AI agents
  • Cloak and uncloak MCP and A2A payloads governed by identity context
  • Comply with EU AI Act and other data minimization requirements
  • Support cross-border Sovereign AI with data leak prevention of identity claims

Support cross-border Sovereign AI and AI data protection with claims cloaking

Ai data minimization with claims cloaking

Flexible deployment options to meet every enterprise requirement

 cards-tick-icon
InCountry multi-tenant is highly scalable with failover and is available in numerous countries
 cards-tick-icon
InCountry single-tenant can be deployed on any cloud including AWS, Microsoft Azure, Google Cloud, Oracle Cloud, and Alibaba Cloud
 cards-tick-icon
AWS Outposts offers servers and racks that can be deployed anywhere and managed with the AWS Console
 cards-tick-icon
On-premises on any cloud for full data sovereignty requires two hosts for the application and the database
Flexible Deployment

The enterprise-grade solution for data protection

Enterprise-Ready
Enterprise-Ready
  • SaaS, single-tenant anywhere, AWS Outposts, and Sovereign Cloud deployment
  • Two points-of-presence with active-active failover
  • Guaranteed messaging across unpredictable networks
Developer-Friendly
Developer-Friendly
  • Invoke via MCP Proxy, MCP Tool, Web Service Proxy, REST API, or CLI
  • Use as skill in Claude Code, OpenCode, Grok Build, OpenAI Codex, and other coding agents
  • Cloak data with generalization, tokenization, hashing, and masking strategies
Bank-Grade Security
Bank-Grade Security
  • Granular policy-based authorization combined with fine-grained authorization from data sources
  • Granular policy-based authorization combined with fine-grained authorization from data sources
  • Searchable encryption using NIST standards
Global Compliance
Global Compliance
  • Data leak prevention across borders and data minimization within brders
  • Detailed support for regulatory approval in complex jurisdictions
  • Full observability with detailed logging and OpenTelemetry dispatch